exam questions

Exam CRISC All Questions

View all questions & answers for the CRISC exam

Exam CRISC topic 1 question 673 discussion

Actual exam question from Isaca's CRISC
Question #: 673
Topic #: 1
[All CRISC Questions]

Which of the following is the BEST course of action when risk is found to be above the acceptable risk appetite?

  • A. Execute the risk response plan.
  • B. Analyze the effectiveness of controls.
  • C. Maintain the current controls.
  • D. Review risk tolerance levels.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Staanlee
7 months, 3 weeks ago
Selected Answer: D
D. Review risk tolerance levels. When risk is found to be above the acceptable risk appetite, the best course of action is to review risk tolerance levels. This involves reassessing the organization's tolerance for the specific risk and determining whether the current risk appetite and thresholds are still appropriate. Before executing the risk response plan or making significant changes to controls, it's essential to ensure that the risk tolerance levels are correctly defined and aligned with the organization's objectives and strategies. Reviewing risk tolerance allows for a more informed decision-making process, and it may lead to adjustments in the risk management approach, including changes to controls, risk acceptance, or other risk response actions.
upvoted 1 times
...
CbtL
1 year ago
Selected Answer: A
Going with A, as the risk response plan is expected to be the implementation of how to handle the risk, which could be several options (mitigate, accept, etc.)
upvoted 2 times
...
john_boogieman
1 year, 2 months ago
Selected Answer: A
Correction, reason: The risk response plan outlines the actions that should be taken when a risk exceeds the acceptable risk level. The response could be to mitigate the risk, transfer the risk, avoid the risk, or accept the risk. The plan should have been developed during the risk management planning phase and should be reviewed periodically to ensure that it remains relevant and effective. Therefore, executing the risk response plan would be the most appropriate action to take in this situation.
upvoted 3 times
...
Julianleehk
1 year, 2 months ago
should be A
upvoted 2 times
...
john_boogieman
1 year, 2 months ago
Selected Answer: B
Just mentioning the CRISC manual does not justify a bad answer. The tolerance level is a deviation from the risk appetite and when this happens what it is about is analyzing the cause, which is usually a lack of effectiveness of the controls.
upvoted 1 times
...
fora
2 years ago
Selected Answer: B
B is correct guys. C'mon, C & D are obviously incorrect.
upvoted 1 times
...
Log4J
2 years ago
CRISC Manual 7th edition p.69. Support answer D. Tolerance levels need to be reviewed even if the risk is above the appetite.
upvoted 3 times
...
Raj1510
2 years, 3 months ago
agree A
upvoted 2 times
...
Josh93
3 years ago
Should be A
upvoted 2 times
...
travdaman
3 years, 3 months ago
Should be A, if risks above acceptable lvl, u need compensation controls. Compensation or additional controls come from risk response plan.
upvoted 2 times
...
Rooks
3 years, 7 months ago
Shouldn’t it be D - review the threshold?
upvoted 1 times
Rooks
3 years, 7 months ago
Or it could be A - execute the risk response plan to lower the risk to acceptable level. Answer B does not make any sense for this question.
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago